<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<Events>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}"/>
      <EventID>4688</EventID>
      <Version>2</Version>
      <Level>0</Level>
      <Task>13312</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8020000000000000</Keywords>
      <TimeCreated SystemTime="2020-06-17T14:27:41.3945738Z"/>
      <EventRecordID>5385</EventRecordID>
      <Correlation/>
      <Execution ProcessID="4" ThreadID="212"/>
      <Channel>Security</Channel>
      <Computer>DESKTOP-4AR7BIA</Computer>
      <Security/>
    </System>
    <EventData>
      <Data Name="SubjectUserSid">S-1-5-18</Data>
      <Data Name="SubjectUserName">-</Data>
      <Data Name="SubjectDomainName">-</Data>
      <Data Name="SubjectLogonId">0x3e7</Data>
      <Data Name="NewProcessId">0x294</Data>
      <Data Name="NewProcessName">C:\Windows\System32\lsass.exe</Data>
      <Data Name="TokenElevationType">%%1936</Data>
      <Data Name="ProcessId">0x200</Data>
      <Data Name="CommandLine"/>
      <Data Name="TargetUserSid">S-1-0-0</Data>
      <Data Name="TargetUserName">-</Data>
      <Data Name="TargetDomainName">-</Data>
      <Data Name="TargetLogonId">0x0</Data>
      <Data Name="ParentProcessName">C:\Windows\System32\wininit.exe</Data>
      <Data Name="MandatoryLabel">S-1-16-16384</Data>
    </EventData>
  </Event>
</Events>
